03/29

// 2023-03-29 // SITUATIONAL AWARENESS // CrowdStrike Tracking Active Intrusion Campaign Targeting 3CX Customers // : crowdstrike

https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
// 2023-03-29 // SITUATIONAL AWARENESS // CrowdStrike Tracking Active Intrusion Campaign Targeting 3CX Customers // : crowdstrike

Spyware vendors use 0-days and n-days against popular platforms

https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/
Spyware vendors use 0-days and n-days against popular platforms

奇安信威胁情报中心

https://ti.qianxin.com/blog/articles/Analysis-of-In-the-wild-Attack-Samples-Exploiting-Outlook-Privilege-Escalation-Vulnerability-(CVE-2023-23397)-EN/
奇安信威胁情报中心

QCon Keynote - Google スライド

https://docs.google.com/presentation/d/1wOT5kOWkQybVTHzB7uLXpU39ctYzXpOs2xVyD4zuYXY/edit?usp=drivesdk
QCon Keynote - Google スライド

GitHub - vanhoefm/macstealer

https://github.com/vanhoefm/macstealer
GitHub - vanhoefm/macstealer

Cobalt Strike 2023 Roadmap and Strategy Update | Cobalt Strike

https://www.cobaltstrike.com/blog/cobalt-strike-2023-roadmap-and-strategy-update/
Cobalt Strike 2023 Roadmap and Strategy Update | Cobalt Strike

The DEA Bought Customer Data from Rogue Employees Instead of Getting a Warrant

https://www.vice.com/en/article/3akn8v/the-dea-bought-customer-data-airlines-parcel-bus-amtrak-no-warrant
The DEA Bought Customer Data from Rogue Employees Instead of Getting a Warrant

CyberChef Malware Analysis - DCRat Loader - YouTube

https://www.youtube.com/watch?v=rpp6BZYIziM
CyberChef Malware Analysis - DCRat Loader - YouTube

signature-base/gen_mal_3cx_compromise_mar23.yar at master · Neo23x0/signature-base · GitHub

https://github.com/Neo23x0/signature-base/blob/master/yara/gen_mal_3cx_compromise_mar23.yar
signature-base/gen_mal_3cx_compromise_mar23.yar at master · Neo23x0/signature-base · GitHub

Pause Giant AI Experiments: An Open Letter - Future of Life Institute

https://futureoflife.org/open-letter/pause-giant-ai-experiments/
Pause Giant AI Experiments: An Open Letter - Future of Life Institute

Google finds more Android, iOS zero-days used to install spyware

https://www.bleepingcomputer.com/news/security/google-finds-more-android-ios-zero-days-used-to-install-spyware/
Google finds more Android, iOS zero-days used to install spyware